LoFP LoFP / valid change in the guardduty (e.g. to ignore internal scanners)

Techniques

Sample rules

AWS GuardDuty Important Change

Description

Detects updates of the GuardDuty list of trusted IPs, perhaps to disable security alerts against malicious IPs.

Detection logic

condition: selection_source
selection_source:
  eventName: CreateIPSet
  eventSource: guardduty.amazonaws.com